Skip to content

Commit d9cb6b1

Browse files
Update templates.
1 parent f3984ce commit d9cb6b1

File tree

2 files changed

+42
-14
lines changed

2 files changed

+42
-14
lines changed

.github/SECURITY.md

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,13 @@
1-
# Python cx_Oracle Security
1+
# Reporting Security Vulnerabilities
22

3-
## Reporting a Vulnerability
3+
Oracle values the independent security research community and believes that responsible disclosure of security vulnerabilities helps us ensure the security and privacy of all our users.
44

5-
See https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html for how to report security issues.
5+
Please do NOT raise a GitHub Issue to report a security vulnerability. If you believe you have found a security vulnerability, please submit a report to [email protected] preferably with a proof of concept. We provide additional information on [how to report security vulnerabilities to Oracle](https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html) which includes public encryption keys for secure email.
6+
7+
We ask that you do not use other channels or contact project contributors directly.
8+
9+
Non-vulnerability related security issues such as great new ideas for security features are welcome on GitHub Issues.
10+
11+
## Security-Related Information
12+
13+
We will provide security related information such as a threat model, considerations for secure use, or any known security issues in our documentation. Please note that labs and sample code are intended to demonstrate a concept and may not be sufficiently hardened for production use.

CONTRIBUTING.md

Lines changed: 31 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,24 +1,44 @@
1-
# Contributing to cx_Oracle
1+
# Contributing
22

3-
*Copyright (c) 2017, Oracle and/or its affiliates. All rights reserved.*
3+
We welcome your contributions! There are multiple ways to contribute.
44

5-
Pull requests can be made under
6-
[The Oracle Contributor Agreement](https://www.oracle.com/technetwork/community/oca-486395.html)
7-
(OCA).
5+
## Issues
86

9-
For pull requests to be accepted into cx_Oracle, the bottom of
10-
your commit message must have the following line using your name and
11-
e-mail address as it appears in the OCA Signatories list.
7+
For bugs or enhancement requests, please file a GitHub issue unless it's security related. When filing a bug remember that the better written the bug is, the more likely it is to be fixed. If you think you've found a security vulnerability, do not raise a GitHub issue and follow the instructions on our [Security Policy](./.github/SECURITY.md).
128

13-
```
9+
## Contributing Code
10+
11+
We welcome your code contributions. To get started, you will need to sign the [Oracle Contributor Agreement](https://www.oracle.com/technetwork/community/oca-486395.html) (OCA).
12+
13+
For pull requests to be accepted, the bottom of your commit message must have
14+
the following line using the name and e-mail address you used for the OCA.
15+
16+
```text
1417
Signed-off-by: Your Name <[email protected]>
1518
```
1619

1720
This can be automatically added to pull requests by committing with:
1821

19-
```
22+
```text
2023
git commit --signoff
21-
````
24+
```
2225

2326
Only pull requests from committers that can be verified as having
2427
signed the OCA can be accepted.
28+
29+
### Pull request process
30+
31+
1. Fork this repository
32+
1. Create a branch in your fork to implement the changes. We recommend using
33+
the issue number as part of your branch name, e.g. `1234-fixes`
34+
1. Ensure that any documentation is updated with the changes that are required
35+
by your fix.
36+
1. Ensure that any samples are updated if the base image has been changed.
37+
1. Submit the pull request. *Do not leave the pull request blank*. Explain exactly
38+
what your changes are meant to do and provide simple steps on how to validate
39+
your changes. Ensure that you reference the issue you created as well.
40+
1. We will review your PR before it is merged.
41+
42+
## Code of Conduct
43+
44+
Follow the [Golden Rule](https://en.wikipedia.org/wiki/Golden_Rule). If you'd like more specific guidelines see the [Contributor Covenant Code of Conduct](https://www.contributor-covenant.org/version/1/4/code-of-conduct/)

0 commit comments

Comments
 (0)